TLCDesk
Privacy Policy Terms of Service tlcdesk.com
English
  • English
  • Español
  • বাংলা
  • ქართული
  • Русский
  • 简体中文
  • العربية
Legal

TLCDesk Privacy Policy

Version 1.2 · Effective date: 2026-07-31

  1. 1. Information We Collect
    • 1.1 Account information
    • 1.2 Driver verification (drivers only)
    • 1.3 Owner and vehicle verification (owners only)
    • 1.4 Payment information
    • 1.5 Rental activity
    • 1.6 Location (required during an active rental)
    • 1.7 Mileage (optional, driver-controlled)
    • 1.8 Communication
    • 1.9 Usage and device data
  2. 2. How We Use Information
  3. 3. Who We Share Information With
  4. 4. Data Retention
  5. 5. Account Deletion — What Actually Happens
  6. 6. Security
  7. 7. Your Rights and Choices
  8. 8. New York and Other State Rights
  9. 9. Children
  10. 10. International Users
  11. 11. Changes to This Policy
  12. 12. Contact

Xponzy Tech LLC, a New York limited liability company doing business as TLCDesk, 418 Broadway STE R, Albany, NY 12207-2922 ("TLCDesk," "we," "us"), operates the TLCDesk mobile application, the owner portal at my.tlcdesk.com, the website at tlcdesk.com, and related services (the "Service"). This policy explains what information we collect, why, who we share it with, how long we keep it, and the choices you have.

Plain-language summary: we collect what is needed to verify drivers and vehicles, run rentals and payments, and keep records the law requires. We do not sell your personal information and we do not use it for advertising. Mileage tracking is optional and controlled by you; sharing the vehicle's location with its owner is required while your rental is active.

1. Information We Collect

1.1 Account information

  • Email address (authentication and account recovery).
  • Full name (profile display, rental contracts, dispute resolution).
  • Role (driver, owner, or staff member of an owner's workspace).
  • Password — stored only as a salted hash. We never store or see your plaintext password.
  • Optional phone number and profile photo.

1.2 Driver verification (drivers only)

  • NYC TLC Driver License number, issue and expiration dates, checked against the NYC Taxi & Limousine Commission's public records.
  • New York State DMV driver license: a photo of the license, its number, issue date, and expiration date. The issue date confirms the license was held at least one year, as required to rent.
  • Date of birth (to confirm you are 21 or older and to complete the rental agreement).
  • Proof of address (a utility bill, bank statement, lease, or government mail from the last 90 days).
  • Emergency contact name and phone/email, captured per rental application.
  • Optional E-ZPass account number (used only to reconcile toll charges on your rentals).

1.3 Owner and vehicle verification (owners only)

  • Owner full address and contact phone (used in rental agreements).
  • Vehicle details: make, model, year, VIN, TLC permit plate number, photos.
  • New York State vehicle registration and the vehicle's NYC TLC For-Hire Vehicle License.
  • FH-1 For-Hire Insurance Certificate details (insured vehicle, carrier, policy number, policy dates).
  • Optional business details: business name, entity type, EIN, NY business registration number and document.

1.4 Payment information

  • Card details (number, CVC, expiration, ZIP) are collected and tokenized by Stripe, Inc. and never stored on our servers. We keep a Stripe customer ID and references to payments, subscriptions, and refunds.
  • Charge history: deposits, weekly rent, subscription invoices, refunds, and payout records.

1.5 Rental activity

  • Applications and bookings (vehicle, driver, timestamps, message to owner, insurance decision, dispute outcome).
  • Rentals (dates, weekly rate, deposit amounts, payment status).
  • Signed rental agreement PDFs, with signature audit data: signer name, signing timestamp, IP address, and device user-agent (kept as the legal attribution record for electronic signatures).
  • Pickup and return documentation: photos of the vehicle's condition and odometer readings.
  • Deposit deductions submitted by the owner (type, amount, reason, evidence photos) and dispute responses from the driver.
  • Vehicle violations synced from NYC public records (summons number, violation type, fine amounts, issue date, payment status), matched to a vehicle by its plate and attributed to the driver renting on the issue date.

1.6 Location (required during an active rental)

  • While your rental is active or past due, the app shares the vehicle's current location with its owner so they can locate their vehicle. This is required for the rental, not a setting you switch on or off — it starts with the rental and stops when the rental ends.
  • We store one current position per rental (latitude, longitude, accuracy, heading, timestamp), overwritten with each update — not a route or movement history.
  • The owner can see this position only while the rental is active or past due — access is enforced at the database layer, not just in the app. The owner cannot see it before the rental starts or after it ends, and never sees a route or a history.
  • If you deny or later revoke the location permission on your phone, the app stops reporting new positions and notifies the owner that location sharing has stopped. The position last reported stays stored and stays visible to the owner for the rest of the rental.
  • When the rental ends, the app clears the last reported position if it is running at that moment. If it is not, that position stays stored — no owner can see it any more, and nothing deletes it on a timer. Email support@tlcdesk.com and we will remove it.

1.7 Mileage (optional, driver-controlled)

  • If a driver separately opts in to automatic mileage tracking, we store daily mile totals only (date, tenths of miles, source), never routes or coordinates. Distance is computed on the driver's phone; only the day's total is uploaded.
  • Drivers may also add or edit manual daily entries and delete their own entries.
  • The owner of a vehicle can see mileage totals attributed to rentals of that vehicle (date, miles, renting driver) for business and tax record-keeping.

1.8 Communication

  • Messages between driver and owner through in-app messaging.
  • Support requests and related correspondence.

1.9 Usage and device data

  • Session timestamps (login, logout) and device metadata (platform, OS version, app version).
  • Push notification tokens (Apple/Google device tokens), if you enable push.
  • Error and crash reports.

We do not collect data from data brokers and we do not run third-party advertising or tracking SDKs.

2. How We Use Information

  • To run the marketplace: verification, listings, applications, agreements, pickups, returns.
  • To verify driver and vehicle credentials against NYC public records.
  • To process payments, deposits, refunds, and owner subscriptions through Stripe.
  • To generate and preserve signed rental agreements and their signature audit records.
  • To share the vehicle's location with its owner while a rental is active, and to operate optional features you enable (mileage tracking).
  • To surface city violation records for listed vehicle plates and notify affected parties.
  • To mediate deposit and insurance disputes using the evidence the parties submit.
  • To send transactional notifications (push and email) about payments, documents, rentals, and violations.
  • To prevent fraud, enforce our Terms, and protect the Service.
  • To comply with legal obligations, including tax record-keeping and lawful requests from authorities.

We do not sell personal information, and we do not use your information for third-party advertising or profiling.

3. Who We Share Information With

  • Stripe, Inc. — Payment processing: cards, deposits, subscriptions, refunds, payouts, and identity checks Stripe requires for owner payout accounts (Stripe Connect). See stripe.com/privacy.
  • The vehicle owner and their insurance broker — Your driver document packet (licenses, proof of address, certificates) and contact details — shared only for a rental you apply to, and only after you give document-sharing consent in the application. You can withdraw the consent; withdrawal cuts off their access.
  • The other party to your rental — Information needed to perform the rental: names, contact details in the agreement, vehicle location while the rental is live, mileage attributed to the owner's vehicle, violation records, deduction evidence.
  • Apple / Google — Push notification delivery (device push tokens and notification content pass through APNs / FCM).
  • NYC Open Data — We query the city's public TLC-license and violation datasets using only the license or plate number — not your name or other personal details.
  • Law enforcement / courts — Only when required by a valid subpoena, warrant, or court order, or to prevent imminent harm.

We have no other categories of recipients. We do not share with advertisers or data brokers.

4. Data Retention

  • Account data — while your account exists. Anonymized when your account deletion completes (Section 5).
  • Rental records (bookings, rentals, weekly charges, payout records, deposit deductions) — at least 7 years, for IRS and TLC record-keeping. They are not deleted when you delete your account.
  • Signed rental agreement PDFs — kept after account deletion; they are the other party's contract as much as yours, and they are tax and legal records.
  • Pickup/return documentation and deduction evidence — while the rental record they support may still be needed. The files you uploaded are deleted from storage when your account deletion completes.
  • Messages — message rows stay so the other party keeps their copy of the conversation; on account deletion your message text is replaced with "[deleted]".
  • Driver and vehicle documents (license photos, proof of address, registration, FHV license, FH-1) — while your account exists; deleted from storage when your account deletion completes.
  • Location position — one current row per rental, overwritten on each update. The app clears it when the rental ends if it is running at that moment; otherwise the row stays until we remove it on request (Section 1.6).
  • Mileage logs — while your account exists; deleted outright when your account deletion completes.
  • Payment data at Stripe — per Stripe's retention policies.

These are how long we keep data, not an automatic purge schedule: we do not run a job that deletes data the moment a period passes. Data is removed when your account deletion completes, as described in Section 5, or when we no longer need it and no legal, tax, or contractual obligation requires us to keep it. If you want something removed sooner, email support@tlcdesk.com — we will remove it unless the law or another person's rights in it require us to keep it.

5. Account Deletion — What Actually Happens

You can request deletion in the app (Account section). The request has a grace period (currently 7 days) during which you can cancel it. Deletion cannot complete while you have an active rental or an open money dispute — end the rental or resolve the dispute first.

When deletion completes:

  • Your profile is anonymized (name becomes "Deleted User"; phone, address, date of birth, licenses, business details, and document references are cleared) and your login email is replaced so it can no longer identify you.
  • Your license numbers and verification PII are scrubbed.
  • Your uploaded documents (licenses, proof of address, insurance and registration documents, pickup/return photos you uploaded, deduction evidence you submitted, insurance-denial proofs) are deleted from storage.
  • Your message text is replaced with "[deleted]"; your notifications, notification preferences, push tokens, bookkeeping entries, and mileage logs are deleted.
  • Your sessions and refresh tokens are revoked; your listings are unpublished.

What is retained, in anonymized or reference form, because the law requires it, another person has rights in it, or it is not on an automatic deletion path:

  • Financial records: rentals, weekly charge history, transfers, and deposit deductions (tax and audit retention — at least 7 years).
  • Signed rental agreement PDFs (the other party's contract).
  • Documents in your storage folder that belong to another live account (for example, fleet documents a manager uploaded for a different owner) are kept for that account.
  • A last shared vehicle position that the app never cleared at the end of a rental (Section 1.6). No one can see it once that rental has ended; ask us to remove it at support@tlcdesk.com.

6. Security

  • All data in transit is encrypted (HTTPS / TLS 1.2+).
  • Data at rest is stored on servers we operate in the United States.
  • Row-level security in the database enforces that each user can access only their own records and the records of parties to their rentals — including location (live rentals only) and consent-gated documents.
  • Card data is handled by Stripe under its PCI-DSS Level 1 compliance; we never store card numbers.
  • Passwords are stored as salted hashes; administrative credentials are never shipped in the app.
  • Administrative configuration changes require admin role plus a second authentication factor.

Breach notification (New York GBL § 899-aa). If a security breach exposes your private information as defined by New York's SHIELD Act, we will notify you in the most expedient time possible consistent with law-enforcement needs, and will notify the New York Attorney General and other authorities as required. We maintain the administrative, technical, and physical safeguards described above as part of our data-security program under GBL § 899-bb.

7. Your Rights and Choices

  • Access and correction. View and correct your profile information in the app's Account screens.
  • Deletion. Request account deletion in the app (see Section 5), or email support@tlcdesk.com.
  • Location. Sharing the vehicle's location with its owner is required while your rental is active (Section 1.6); there is no in-app switch for it, and it stops when the rental ends. You can deny or revoke the permission on your phone — the app then stops reporting and notifies the owner. To have a stored position removed, email support@tlcdesk.com.
  • Mileage. Automatic mileage tracking is off by default and is a separate opt-in; you can edit or delete your manual entries.
  • Document-sharing consent. You choose whether to share your document packet per application; you may withdraw consent, which cuts off the owner's and broker's access.
  • Push notifications. Control them in your device settings and in-app preferences; operational notices about active obligations may still be sent by email.
  • Export. Ask us for a machine-readable export of your rental history: support@tlcdesk.com.

To exercise any right, use the in-app controls or email support@tlcdesk.com with the subject "Privacy Request" from the email on your account. We verify requests using your account email. We do not discriminate against you for exercising your rights.

8. New York and Other State Rights

New York residents have the breach-notification rights described in Section 6 and may contact us with privacy questions at any time. If you reside in a state with a comprehensive consumer privacy law (for example, California's CCPA/CPRA), you may have rights to know, access, correct, delete, and port personal information, and the right to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of; the remaining rights are honored through the mechanisms in Section 7, and we will not discriminate against you for exercising them. You may use an authorized agent where your state's law provides for one; we will verify the agent's authority.

9. Children

The Service is for adults 18 and older, and drivers must be at least 21 to rent. The Service is not directed at anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.

10. International Users

The Service is operated from and directed at the United States, specifically New York City. If you access it from elsewhere, your information is processed in the United States.

11. Changes to This Policy

We will notify users of material changes through the app and, where practical, by email, before they take effect. The effective date at the top reflects the latest revision.

12. Contact

Xponzy Tech LLC d/b/a TLCDesk

418 Broadway STE R, Albany, NY 12207-2922

Privacy requests: support@tlcdesk.com (subject "Privacy Request")

Legal: legal@tlcdesk.com

Phone: 516-780-8094

TLCDesk
Privacy Policy Terms of Service

© 2026 Xponzy Tech LLC · 418 Broadway STE R, Albany NY 12207-2922 · legal@tlcdesk.com